CVE Number – CVE-2018-8569
A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit this vulnerability, an attacker needs to convince the victim to click the special URL in the desktop application that redirect to the attacker-controlled web-page. After the content from attacker-controlled web-page is loaded by the desktop application, the attacker can gain control of the victim’s machine.
The security update addresses the vulnerability by disallowing loading of arbitrary content in the desktop application.
You can download the update here.
Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.